It is about deciding what is even in the room.
Most teams treat security as an access problem. Who can log in, who has admin rights, who got offboarded properly. That is table stakes. The bigger risk sits one layer deeper: how much data a legitimate, currently-employed, correctly-permissioned user can actually see.
Profiles get built once and never revisited. Permission Sets pile up as people change roles, take on projects, or move teams. Nobody removes access, they just add more on top. Years later, half your org has visibility into data that has nothing to do with their actual job. Not because anyone decided they should have it. Because nobody decided they shouldn't.
That too is part Security Cleanup. Not just "can this person get in," but "once they're in, how much can they see that they have no business seeing." Sharing Rules, Role Hierarchy, Permission Set Groups, all the layers that quietly accumulate access nobody remembers granting.
Hardening access keeps strangers out. Reducing data exposure keeps insiders honest, by design instead of by trust.
Book a free 60-minute Salesforce Technical Debt Audit: a score for Usability and Build Quality, and your top cleanup priorities.